CVE-2025-5739: TOTOLINK X15 HTTP POST Request formSaveConfig buffer overflow
A vulnerability classified as critical has been found in TOTOLINK X15 1.0.0-B20230714.1105. This affects an unknown part of the file /boafrm/formSaveConfig of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5739?
CVE-2025-5739 is classified as a critical vulnerability.
How does CVE-2025-5739 affect the TOTOLINK X15?
CVE-2025-5739 affects the HTTP POST Request Handler in TOTOLINK X15, leading to a buffer overflow through manipulated arguments.
What component is impacted by CVE-2025-5739?
CVE-2025-5739 impacts the file /boafrm/formSaveConfig within the TOTOLINK X15.
Can CVE-2025-5739 be exploited remotely?
Yes, the vulnerable HTTP POST Request Handler in the TOTOLINK X15 can be exploited remotely.
What measures can be taken to mitigate CVE-2025-5739?
To mitigate CVE-2025-5739, ensure that the TOTOLINK X15 is updated to the latest firmware version that addresses this vulnerability.